---
title: CVEs by release
hide_title: true
sidebar_position: 2
---

#### Version 2.1.0

| CVE            | Title                                                                   | Affected          |
| :------------- | :---------------------------------------------------------------------- | -----------------:|
| CVE-2023-25504 | Possible SSRF on import datasets                                        | <= 2.1.0          |
| CVE-2023-27524 | Session validation vulnerability when using provided default SECRET_KEY | <= 2.1.0          |
| CVE-2023-27525 | Incorrect default permissions for Gamma role                            | <= 2.1.0          |
| CVE-2023-30776 | Database connection password leak                                       | <= 2.1.0          |


#### Version 2.0.1

| CVE            | Title                                                       | Affected          |
| :------------- | :---------------------------------------------------------- | -----------------:|
| CVE-2022-41703 | SQL injection vulnerability in adhoc clauses                | < 2.0.1 or <1.5.2 |
| CVE-2022-43717 | Cross-Site Scripting on dashboards                          | < 2.0.1 or <1.5.2 |
| CVE-2022-43718 | Cross-Site Scripting vulnerability on upload forms          | < 2.0.1 or <1.5.2 |
| CVE-2022-43719 | Cross Site Request Forgery (CSRF) on accept, request access | < 2.0.1 or <1.5.2 |
| CVE-2022-43720 | Improper rendering of user input                            | < 2.0.1 or <1.5.2 |
| CVE-2022-43721 | Open Redirect Vulnerability                                 | < 2.0.1 or <1.5.2 |
| CVE-2022-45438 | Dashboard metadata information leak                         | < 2.0.1 or <1.5.2 |
